CVE-2023-41990 is a critical arbitrary code execution vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS, triggered by processing a maliciously crafted font file. With a CVSS score of 7.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L), allowing an attacker to achieve high confidentiality, integrity, and availability impacts (C:H/I:H/A:H). Apple has confirmed active exploitation against versions of iOS released before 15.7.1, and it is listed in CISA's KEV catalog. While no public exploit code is available, the vulnerability has garnered significant community discussion and media coverage, particularly in relation to the "Operation Triangulation" spyware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 15.7.8CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.7.8CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 11.7.9CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.